vendor:
WinFTP server
by:
KaGra
7.5
CVSS
HIGH
Denial of Service (DoS)
399
CWE
Product Name: WinFTP server
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: No
Related CWE:
CPE: a:winftp:server:1.6
Platforms Tested: Windows XP SP1 English version
Unknown
WinFTP server ver 1.6 D.o.S Exploit
Sending a username and a buffer of 1500 bytes as a password to the WinFTP server version 1.6 will crash the server. The server will crash when it is not minimized on the target computer, or when it stops being minimized. If the exploit is used in a loop without ending, the server will be unable to restart. Most commands of the FTP service are vulnerable.
Mitigation:
Upgrade to a patched version of WinFTP server.